d3d.dll

Windows Live Updates

Mircosoft Corporation

The library d3d.dll has been detected as malware by 26 anti-virus scanners.
Publisher:
Mircosoft Corporation

Product:
Windows Live Updates

Version:
2.0.2.3

MD5:
3bb4f700ae234ce0efe6e46c30cecb55

SHA-1:
fd60d026b7428ed41db8907263f3209fcef24567

SHA-256:
704e060a3d068c5ce2ce63adaf444d5910e02db16acf382b3f9714f1ccc0cdfd

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
5/10/2024 10:13:58 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.397835
701

Agnitum Outpost
Trojan.Agent
7.1.1

Avira AntiVirus
TR/Spy.Gen
7.11.213.138

avast!
Win32:Malware-gen
2014.9-150306

AVG
MSIL3
2016.0.3179

Baidu Antivirus
Trojan.MSIL.Agent
4.0.3.1536

Bitdefender
Gen:Variant.Kazy.397835
1.0.20.325

Comodo Security
UnclassifiedMalware
21297

Emsisoft Anti-Malware
Gen:Variant.Kazy.397835
8.15.03.06.12

ESET NOD32
MSIL/Agent.OFX (variant)
9.11271

Fortinet FortiGate
MSIL/Agent.OFX!tr
3/6/2015

F-Secure
Gen:Variant.Kazy.397835
11.2015-06-03_6

G Data
Gen:Variant.Kazy.397835
15.3.25

IKARUS anti.virus
Trojan.Spy
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.200.15159

Kaspersky
Trojan.MSIL.Agent
14.0.0.2390

McAfee
RDN/Generic PWS.y!bbh
5600.6835

MicroWorld eScan
Gen:Variant.Kazy.397835
16.0.0.195

Norman
Suspicious_Gen4.GOJLV
11.20150306

Panda Antivirus
Trj/CI.A
15.03.06.12

Qihoo 360 Security
Win32/Trojan.d51
1.0.0.1015

Quick Heal
Trojan.Agen.r4
3.15.14.00

Sophos
Mal/MSIL-HL
4.98

Trend Micro House Call
TROJ_SCARPNEX.B
7.2.65

Trend Micro
TROJ_SCARPNEX.B
10.465.06

VIPRE Antivirus
Trojan.Win32.Generic
38130

File size:
132.5 KB (135,680 bytes)

Product version:
2.0.2.3

Copyright:
Copyright © Mircosoft Corporation 2010

Original file name:
d3d.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\ProgramData\application data\updates\d3d.dll

File PE Metadata
Compilation timestamp:
1/24/2013 8:14:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:ATOBBY4OWJAvL8eDnfYNc6K3ZC6coJZnIRwknc4wB7XTrmo9xSJ3/O:qpA2dcoJbbPmo9g

Entry address:
0x21F6E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.6421

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
128 KB (131,072 bytes)

Remove d3d.dll - Powered by Reason Core Security